CVE-2022-27623: Critical severity synology photos diskstation manager vulnerability
Missing authentication for critical function vulnerability in iSCSI management functionality in Synology DiskStation Manager (DSM) before 7.1-42661 allows remote attackers to read or write arbitrary files via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-27623?
CVE-2022-27623 is a vulnerability that allows remote attackers to read or write arbitrary files in the iSCSI management functionality in Synology DiskStation Manager (DSM) before 7.1-42661.
What is the severity of CVE-2022-27623?
CVE-2022-27623 has a severity rating of critical with a score of 9.1.
How does CVE-2022-27623 impact Synology DiskStation Manager (DSM)?
CVE-2022-27623 allows remote attackers to read or write arbitrary files in the iSCSI management functionality of Synology DiskStation Manager (DSM) before version 7.1-42661.
How can a remote attacker exploit CVE-2022-27623?
Remote attackers can exploit CVE-2022-27623 by sending unspecified vectors to the iSCSI management functionality of Synology DiskStation Manager (DSM) before version 7.1-42661.
Is there a fix for CVE-2022-27623?
Yes, a fix is available for CVE-2022-27623. Users should update their Synology DiskStation Manager (DSM) to version 7.1-42661 or later.